diff --git a/.github/workflows/quality.yml b/.github/workflows/quality.yml new file mode 100644 index 000000000..61c4808a5 --- /dev/null +++ b/.github/workflows/quality.yml @@ -0,0 +1,36 @@ +name: Quality Checks + +on: + push: + branches: [master, main] + pull_request: + +permissions: + contents: read + +jobs: + checks: + runs-on: ubuntu-latest + + steps: + - name: Checkout repository + uses: actions/checkout@v4 + + - name: Set up PHP + uses: shivammathur/setup-php@v2 + with: + php-version: '8.4' + extensions: curl, gd, mbstring + coverage: none + + - name: Validate composer.json + run: composer validate --no-check-publish + + - name: Install dependencies + run: composer install --no-interaction --no-progress + + - name: Check view output escaping + run: composer xss:check + + - name: Check code style + run: composer format:check diff --git a/.php-cs-fixer.php b/.php-cs-fixer.php index cfd47c661..de8924f05 100644 --- a/.php-cs-fixer.php +++ b/.php-cs-fixer.php @@ -4,6 +4,8 @@ ->notPath('vendor') ->notPath('bootstrap') ->notPath('storage') + // Local development mounts a MySQL data directory here; it is not project code. + ->exclude('docker/data') ->in(__DIR__) ->name('*.php') ->notName('*.blade.php'); diff --git a/AGENTS.md b/AGENTS.md index ff0cf1b81..fb710cc7f 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -29,7 +29,7 @@ Map-OS is an open-source Service Order and Business Management system built in P - Always format PHP code using project standards: `composer format` (which invokes `application/vendor/bin/php-cs-fixer fix`). 2. **Security & Input/Output Handling:** - Always validate user input. - - Always escape output in views using `html_escape()`. + - **Always escape output in views.** Use the helpers in `application/helpers/general_helper.php`, picking the one that matches the output context (see table below). Never `echo` a database row, `$_GET`/`$_POST` value, session value or config value raw. - Never use raw SQL string concatenation; use CodeIgniter Query Builder or query bindings (`?` or `$this->db->where()`) to prevent SQL injection. - Never expose sensitive data (e.g., password hashes) in public models or API responses. 3. **Database Changes:** @@ -37,6 +37,45 @@ Map-OS is an open-source Service Order and Business Management system built in P 4. **Commit Messages:** - Follow [Conventional Commits](https://www.conventionalcommits.org/): `feat`, `fix`, `docs`, `refactor`, `chore`, etc. +## Output Escaping in Views + +Pick the escaper by the context the value lands in. Using the wrong one is a +common source of XSS, so match the row, not just the habit. + +| Helper | Use for | Example | +| --- | --- | --- | +| `esc($v)` | HTML text and quoted attributes | `